[NEWS] Novell iManager OpenSSL ASN Parsing Vulnerability

From: SecuriTeam (support_at_securiteam.com)
Date: 06/15/05

  • Next message: SecuriTeam: "[NEWS] Bluetooth SIG DoS"
    To: list@securiteam.com
    Date: 15 Jun 2005 10:44:33 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Novell iManager OpenSSL ASN Parsing Vulnerability
    ------------------------------------------------------------------------

    SUMMARY

    Novell <http://www.novell.com/products/consoles/imanager/> iManager is a
    Web-based administration console that provides customized access to
    network administration utilities.

    Novell iManager includes an installation of OpenSSL that is vulnerable to
    ASN.1 parsing bugs.

    DETAILS

    Vulnerable Systems:
     * Novell iManager version 2.0.2

    OpenSSL ASN.1 Parsing vulnerability in Apache
    Multiple vulnerabilities were reported in the ASN.1 parsing code in
    OpenSSL. These issues could be exploited to cause a denial of service or
    to execute arbitrary code.
    The server in this case identifies itself as: Apache/2.0.48(Win32)
    mod_ssl/2.0.44 OpenSSL/0.9.7 mod_jk/1.2.4

    When using the exploit downloaded from here:
     
    <http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c>
    http://www.securityfocus.com/data/vulnerabilities/exploits/ASN.1-Brute.c

    The server will stop responding, and an error will occurs.

    The Service is as default installed on port 8443

    Patch Availability:
    These vulnerabilities are corrected in OpenSSL 0.9.7d.
    iManager 2.5 ships with OpenSSL 0.9.7d - to resolve the vulnerability
    upgrading is suggested.

    Disclosure Timeline:
     * 08.01.05 - Vulnerability discovered
     * 17.04.05 - Research ended
     * 18.04.05 - Novell Notified (secure@novell.com)
     * 18.04.05 - Received response from Ed Reed, Security Tzar, Novell, Inc.
     * 03.06.05 - Novell reports issue fixed
     * 13.06.05 - Public release

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:advisory@cirt.dk> Dennis
    Rand.
    The original article can be found at:
    <http://cirt.dk/advisories/cirt-32-advisory.pdf>
    http://cirt.dk/advisories/cirt-32-advisory.pdf

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[NEWS] Bluetooth SIG DoS"

    Relevant Pages

    • [NT] Novell NetWare Client nicm.sys Local Privilege Escalation VulnerabilityNovell NetWare Client ni
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Novell NetWare Client nicm.sys Local Privilege Escalation ... VulnerabilityNovell NetWare Client nicm.sys Local Privilege Escalation ... error vulnerability within Novell Inc.'s NetWare Client allows attackers ...
      (Securiteam)
    • [NT] Novell NetWare Client Local Privilege Escalation Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Novell NetWare Client Local Privilege Escalation Vulnerability ... The Novell Client software provides "a workstation with access to Novell ... the driver nwfilter.sys will be loaded at system startup. ...
      (Securiteam)
    • [UNIX] OpenSSL Multiple Vulnerabilities (Malformed ASN.1, Malformed Public Key)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... and prepared fixes for a number of vulnerabilities in the OpenSSL ASN1 ... OpenSSL to parse a client certificate from an SSL/TLS client when it ... resulting in a denial of service vulnerability. ...
      (Securiteam)
    • [UNIX] Trend Micro VirusWall Buffer Overflow in VSAPI Library
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... buffer overflow vulnerability in VSAPI library allows arbitrary code ... is called "vscan" which is set suid root by default. ... permissions and thus granted all local users the privilege to execute the ...
      (Securiteam)
    • [NT] Novell Client Trust Heap Overflow Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Novell Client Trust Heap Overflow Vulnerability ...
      (Securiteam)